1,350 stars · AGPL-3.0 · v3.5.1 (2025-11-21) · Track this in Scout
Shows which running containers have a newer image waiting, as a command or a small web page, and changes nothing by itself.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Cup is a Rust program that reads the containers on a machine and asks each image's registry whether a newer version of that tag exists. It runs as a one-off command, or as a server with a web page and a JSON interface at /api/v3/json.
What it is good for. Anyone running a handful of containers on one machine who currently finds out about an update by reading release notes they happened to see. The honest version of this job is "tell me, and let me decide" — the tools that update automatically are a different and riskier thing. On a Raspberry Pi 5 the author measured 3.7 seconds to check 58 images.
- Very small and very fast. The README puts the binary at 5.4 MB.
- It reports and never acts, so it cannot restart a service at three in the morning.
- A JSON interface means you can feed the result into something else rather than reading a page.
- ⚠ Every documented command mounts the Docker socket,
/var/run/docker.sock, into the container. That socket is equivalent to administrator access on the host machine, so anything that gets into this container gets the machine. - ⚠ The web page and its JSON interface have no password. The only page in the documentation headed "Authentication" is about giving Cup credentials for private image registries, not about protecting Cup itself. The default port is 8000 and no documentation page states which network interfaces it listens on.
- Its newest release, v3.5.1, is dated 21 November 2025 — about ten and a half months ago — while its code was last touched on 22 July 2026. So there is unreleased work, and the released version is the old one. 38 open issues, 6 open pull requests. The licence is AGPL-3.0, which obliges anyone who offers it as a network service to publish their source; the file carries only the Free Software Foundation's own copyright line and names the author nowhere.
- containrrr/watchtower
Did the same checking and then pulled and restarted containers itself, which is the part Cup deliberately refuses to do; archived by its owner on 17 December 2025.
Track this in Scout
mag37/dockcheckChecks the same thing as a plain shell script and can also perform the update, with notifications and image backups, but has no web page.
Track this in Scout
crazy-max/diunWatches registry references rather than running containers, is notification-first with many delivery backends, and never updates anything either.
Track this in Scout
# one-off check of everything on this machine docker run --rm -t \ -v /var/run/docker.sock:/var/run/docker.sock \ ghcr.io/sergi0g/cup check # or run the web page, bound to localhost only docker run -d --name cup \ -v /var/run/docker.sock:/var/run/docker.sock \ -p 127.0.0.1:8000:8000 \ ghcr.io/sergi0g/cup serve -p 8000



